CVE-2021-31798: Medium severity cyberark credential provider vulnerability
Published Sep 2, 2021
·Updated
The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and under certain conditions a local malicious user can obtain the plaintext of cache files.
Affected Software
1 affected component
CyberArk Credential Provider<12.1
Event History
Sep 2, 2021
CVE Published
via MITRE·12:09 AM
Data Sourced
via MITRE·12:09 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-31798.
2
What is the title of this vulnerability?
The title of this vulnerability is 'The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy'.
3
What is the severity level of CVE-2021-31798?
The severity level of CVE-2021-31798 is medium with a severity value of 4.4.
4
What software is affected by CVE-2021-31798?
CyberArk Credential Provider prior to version 12.1 is affected by CVE-2021-31798.
5
How can a local malicious user exploit CVE-2021-31798?
Under certain conditions, a local malicious user can obtain the plaintext of cache files encrypted by CyberArk Credential Provider prior to version 12.1.